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Data Privacy Notice for Associates 


of Capital One Philippines Support Services Corp. 


1. This is to formally inform you that all personal information collected from you at the point of your 
application, and all subsequent information with Capital One Philippines Support Services Corp. 
(COPSSC), such as full name, email address, residence address, phone numbers, signature, picture, 
fingerprints, place of birth, date of birth, age, marital status, nationality, government IDs, Tax 
Account Number, Social Security number, employment information, academic degrees, personal and 
familiar references, personal information of family members, and other sensitive information such 
as education, employment, criminal and medical history, shall be used in processing your application 
for employment with COPSSC, and/ or subsequent employment including but not limited to, 
activities such as education and employment verification, criminal and medical background 
investigation. Any personal information received from third parties will likewise be used for the 
same purpose. 


2. In the event that you provide us with personal information relating to a third party or your family 
member, you acknowledge that you have his/her consent for us to use the information for purposes 
in which they were collected. 


3. We hereby inform you that we have in place administrative, technical, personal and physical 
measures to protect and safeguard your information against loss, misuse, unauthorized access, 
theft, unauthorized modification, disclosure or destruction. We have restricted access to your 
personal information to those associates and non - associates who have a legitimate business need 
for such access. Those with access to your information shall include, among others, Human 
Resources associates who regularly process employment related information (e.g. for payroll). Your 
supervisors and/or managers may also have access to your personal information for purposes of 
contacting you in relation to your work. 


4. COPSSC also provides training to covered associates and non - associates where relevant to promote 
awareness of COPSSC’s requirements and policies surrounding protection and security of your 
personal information 


5. By giving us your personal information, it is understood that you consent to the transfer of such 
information where applicable, to any entity that forms a direct or indirect part of COPSSC, its 
subsidiaries or affiliates, as well as third parties, either local or foreign, including: a) any banking 
institution or other related supplier involved in the processing of payments, b) any person 
connected with us that is involved in service, verification, review or certification processes relating 
to tax and administrative matters, c) any supplier who assists us in ensuring the effective provision 
of the services, d) any company with which we have entered into a cooperation agreement for the 
purpose of promoting and providing their products and services, (for which your consent is 
required), e) any third party in compliance with applicable laws and/or court or administrative 
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orders, and f) the competent authority, where required. In all instances, the one processing your 
personal information shall do so following specific instructions as laid out in the respective 
outsourcing agreement. 


6. Similarly, your personal information may also be processed and shared with third parties or affiliates 
for the following purposes: 


a) Human Resources Management: including but not limited to the normal business practices 
related to the establishment, maintenance and termination of employment relationships. For 
example, the Employee’s application for employment, hiring, his or her role and function in 
COPSSC, employee management and administration generally (including both during and after 
employment), employment verification, administering benefits, administering personal short or 
long-term compensation programs, conducting disciplinary proceedings, addressing labor 
relations issues, processing health insurance claims, and communicating with Employee 
Candidates and Associates. 


b) Operations Management: including but not limited to establishment, performance and 
management of business activities of COPSSC. For example, maintaining and monitoring usage 
of internal networks and information technology systems. 


c) Security Management: including but not limited to ensuring the security of COPSSC’s premises 
and information held by COPSSC as well as the safety of COPSSC’s associates. 


d) Legal and Regulatory Compliance: including but not limited to obtaining and releasing 
Employee Personal Information as required by law (e.g., tax, health and safety, 
antidiscrimination laws) or judicial authorization and to maintain records that can include 
Personal Information, such as government identifiers, information relating to sickness, 
maternity or parental leave, pension and retirement. 


e) Conducting analytics and research such as employee behaviors, preferences, associate 
lifecycle, market data and similar activities. 


7. However, COPSSC may still disclose your personal information to third parties other than those 
mentioned in items #5 and #6 only if required by law or legal order, to protect the interest of 
COPSSC and/or its associates, if there is an emergency situation involving the health and safety of an 
employee, when necessary for COPSSC to perform a contractual obligation owed to an employee or 
for other lawful purposes, such as to establish a claim or defense, or with your consent. 


8. You may be entitled to object to the sharing of your information except when the disclosure is 


required by law, regulations, court order, or where the transfer is necessary to perform an 
obligation owed to you, as a result of your employment with COPSSC. You may also withdraw your 
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10. 


11. 


12. 


13. 


consent for the use of your personal information at any time during your employment with COPSSC. 
However, please note that, upon withdrawal of your consent, we will be unable to process your 
personal information to provide you with any service that would require the processing of your 
information. 


COPSSC will employ reasonable means to keep your personal information accurate, complete, 
up-to-date and reliable. However, it is your responsibility to inform us regarding changes that may 
occur in your personal information. You will be permitted to review and, where inaccurate, correct 
your personal information. However, we reserve the right to deny access to or make changes in your 
personal information, when doing so is disproportionate to the risk and expense required to update 
or correct your personal information. 


For the avoidance of doubt, you agree to share your personal information to any bank, employer or 
entity, who may conduct criminal or background investigation with us. 


COPSSC may also disclose your personal information to any Capital One group of companies and 
their affiliates where such entities need to process your personal information for business or 
business efficiency purposes. COPSSC will ensure that your personal information is protected during 
such disclosure or transfer. Your personal information may also be processed outside the Philippines 
through Amazon Web Services but only to the extent of storage and none other. 


COPSSC will maintain a program to ensure compliance with this Privacy Notice. The Data Privacy 
Team is primarily responsible in implementing and overseeing the administration of this Privacy 
Notice. All associates whose responsibilities include processing of Associate Personal Information 
are required to adhere to this Privacy Notice and any implementing policies. Failure to do so is 
deemed a serious offence, for which disciplinary action may be taken, potentially resulting in 
termination of employment. Equally, the misuse of Associate Personal Information by an individual 
or organization acting as agent or service provider to COPSSC is deemed a serious issue for which 
action may be taken, potentially resulting in the termination of any agreement. 


Finally, consistent with the Data Privacy Act of 2012, its Implementing Rules and Regulations, 
advisory opinions of the National Privacy Commission and existing jurisprudence, you have the 
following rights: 


A) You have the right to be informed, whether personal data pertaining to you shall be, are 
being, or have been processed, including the existence of automated decision-making and 
profiling. For instances not covered by this notice, you shall be notified and furnished with 
information before the entry of your personal data into the processing system of the personal 
information controller, or at the next practical opportunity: (a) Description of the personal data 
to be entered into the system; (b) Purposes for which they are being or will be processed, 
including processing for direct marketing, profiling or historical, statistical or scientific purpose; 
(c) Basis of processing, when processing is not based on your consent; (d) Scope and method of 
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the personal data processing; (e) The recipients or classes of recipients to whom the personal 
data are or may be disclosed; (f) Methods utilized for automated access, if the same is allowed 
by you, and the extent to which such access is authorized, including meaningful information 
about the logic involved, as well as the significance and the envisaged consequences of such 
processing for you; (g) The identity and contact details of the personal information controller or 
its representative; (h) The period for which the information will be stored; and (i) The existence 
of your rights, including the right to access, correction, and object to the processing, as well as 
the right to lodge a complaint before the Commission. 


B) You shall have the right to object to the processing of your personal data, including 
processing for direct marketing, automated processing or profiling. You shall also be notified and 
given an opportunity to withhold consent to the processing in case of changes or any 
amendment to the information supplied or declared to you in the preceding paragraph. When 
you object or withhold consent, the personal information controller shall no longer process the 
personal data, unless: (a) The personal data is needed pursuant to a subpoena; (b) The collection 
and processing are for obvious purposes, including, when it is necessary for the performance of 
or in relation to a contract or service to which you are a part of, or when necessary or desirable 
in the context of an employer-employee relationship between the collector and the data 
subject; or (c) The information is being collected and processed as a result of a legal obligation 


C) That you have the right to reasonable access to, upon demand, the following: (a) Contents of 
your personal data that were processed; (b) Sources from which personal data were obtained; 
(c) Names and addresses of recipients of the personal data; (d) Manner by which such data were 
processed; (e) Reasons for the disclosure of the personal data to recipients, if any; (f) 
Information on automated processes where the data will, or is likely to, be made as the sole 
basis for any decision that significantly affects or will affect you; (g) Date when your personal 
data were last accessed and modified; and (h) The designation, name or identity, and address of 
the personal information controller 


D) You have the right to dispute the inaccuracy or error in the personal data and have the 
personal information controller correct it immediately and accordingly, unless the request is 
unjustified or otherwise unreasonable. If the personal data has been corrected, the personal 
information controller shall ensure the accessibility of both the new and the retracted 
information and the simultaneous receipt of the new and the retracted information by the 
intended recipients thereof: Provided, That recipients or third parties who have previously 
received such processed personal data shall be informed of its inaccuracy and its rectification, 
upon your reasonable request. 


E) You shall have the right to suspend, withdraw or order the blocking, removal or destruction 
of your personal data from the personal information controller’s filing system. This right may be 
exercised upon discovery and substantial proof of any of the following: (a) Your personal data is 
incomplete, outdated, false, or unlawfully obtained; (b) Your personal data is being used for 
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purpose that you do not authorize; (c) Your personal data is no longer necessary for the 
purposes for which they were collected; (d) You withdraw consent or object to the processing, 
and there is no other legal ground or overriding legitimate interest for the processing; (e) The 
personal data concerns private information that is prejudicial to you, unless justified by freedom 
of speech, of expression, or of the press or otherwise authorized; (f) The processing is unlawful; 
(g) The personal information controller or personal information processor violated your rights. 
The personal information controller may notify third parties who have previously received such 
processed personal information. 


F) You shall be indemnified for any damages sustained due to such inaccurate, incomplete, 
outdated, false, unlawfully obtained or unauthorized use of personal data, taking into account 
any violation of your rights and freedom. 


14. Should you not consent to the collection, processing, storage and disposal of your personal 
information as required in this notice, COPSSC may not be able to perform its legal and contractual 


obligation with you. (Sta. by: 


72451BB9CB2C40A... 
Kenji Roy Nakamura 


Associate name and signature : 


Date: 


3/5/2021 


Enterprise ID: DLV183 
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MEDICAL CERTIFICATE VERIFICATION AND CONSENT FORM 


In executing this document and in affixing my signature hereto, I confirm that: 


1. I have freely, knowingly and voluntarily given my consent for Capital One Philippines 
Support Services Corp. (““COPSSC”’) and Maxicare, our health care provider to; 


a. 


Obtain, collect, examine, process, and store copies of my personal information, 
including sensitive personal information, privileged information, medical records 
from the providers, i.e. Medical clinic/s, Hospital/s, Diagnostic laboratory/ies and 
Attending Physician/s, for the purpose of medical certificate verification and Fit to 
Work Clearances including as such the result of my Annual Medical Examination/ 
Executive Check-up and/or results of drug testing screening. Except as otherwise 
stated hereon, any information obtained relative to the authority herein given shall be 
strictly confidential. The extent of the collection and processing shall be necessary 
and incidental to the performance of the services contemplated in the Agreement. 


Disclose and release such information to the Company and its representatives, i.e. HR 
personnel and to my immediate supervisor, Maxicare and its Representatives, 
including the service providers which will perform the services contemplated in the 
Agreement, and relevant government agencies in compliance with the Republic Act 
No. 11223 otherwise known as the “Universal Health Care Act”, its Implementing 
Rules and Regulations, Republic Act No. 11332 otherwise known as the “Mandatory 
Reporting of Notifiable Diseases and Health Events of Public Health Concern Act” 
and other relevant issuances of the Department of Health and/or Philippine Health 
Insurance Corporation, of such information about my current state of well-being and 
determining my fitness for employment or continued employment with COPSSC. 


2. I hereby warrant that I understand my rights and obligations pursuant to the Data Privacy 
Act and its implementing rules and regulations. I understand that I retain the right to: be 
informed, to object, to access, to complain, to rectify, to request for filtering of certain 
information and to corresponding damages in case of violation of our rights within the 
corresponding limitations as set forth in the pertinent laws. 


3. I hereby agree to hold Capital One Philippines Support Services Corp. (““COPSSC”’) and 
Maxicare, its Representatives free and harmless from and against any and all suits or 
claims, actions, or proceedings, damages, costs and expenses, including attorney’s fees, 
which may be filed, charged or adjudged against Capital One Philippines Support 
Services Corp. (“COPSSC”), and Maxicare or any of its directors, stockholders, officers, 
employees, agents, or Representatives in connection with or arising from the use, 
processing and disclosure by Capital One Philippines Support Services Corp. 
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(““COPSSC”) and Maxicare or its Representatives of the aforementioned information 
pursuant to Maxicare reliance on my representation and warranty that Maxicare, the 
Company, and their representatives have the authority to examine, use, process, store, 
share, or disclose, as the case may be, said information for the above-mentioned 
purposes. 


As such, I am executing this document to attest to the truth of the foregoing. 
3/5/2021 


I am signing this document via DocuSign on this in Muntinlupa City, Philippines. 


(Ban by: 
72451BB9CB2C40A... 


Kenji Roy Nakamura 





(Printed Name & Signature) 
Member 
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Electronic Record Signature Disclosure 


Please read this Electronic Record and Signature Disclosure (“ERSD”) carefully. It contains 
important information about receiving and signing Communications electronically. 


The documents in this Envelope are being provided by (a) the Capital One entity listed on your 
account agreement if you are a Customer or (b) by the Capital One entity listed in the documents 
in this Envelope (collectively referred to herein as “we,” “us,” “Company”, or “Capital One”) if 
you are not a Customer. Certain laws may require us to provide specific information (including 
notices and disclosures) to you in writing (“Required Information”), which means you have the 
right to receive such Required Information on paper if you wish. 


By consenting below, you may instead choose to receive all such Required Information 
electronically. We also need your general consent to use electronic signatures, and to send you 
other types of Communications in connection with our relationship with you electronically 
(Required Information and other Communications are collectively referred to herein as 
“Communications”). 


Scope 


“Communications” means information or documents included in this Envelope such as 
disclosures, notices, authorizations, acknowledgements, agreements, undertakings, fee schedules, 
periodic statements, or other information as part of a Capital One account enrollment, setup, or 
servicing. Communications may also include certain tax statements or forms, which may include, 
but are not limited to, Forms 1098, 1098-E, 1098-MA, 1098-T,1099-A, B, C, CAP, DIV, G, H, 
INT, K, LTC, MISC, OID, PATR, Q, R, S, SA, 3921, 3922, 5498, 5498-ESA, and 5498-SA and 
Schedule K-1 (“Tax Documents”). In addition to all the terms contained in this ERSD, including 
with respect to your right to paper copies, your right to withdraw your consent and the hardware 
and software necessary to access and retain Tax Documents, each of the following applies to the 
electronic delivery of Tax Documents: 


e You are not required to receive Tax Documents electronically. If you do not want to 
receive them electronically, do not agree to this ERSD by clicking the Decline to Sign 
button. 

e If you consent to receive the Tax Documents contained within this Envelope 
electronically, your consent will apply only for Tax Documents required to be delivered 
after the date of the consent (which are typically Tax Documents that are required to be 
delivered by January 31st or February 15th, as applicable, of the relevant year until 
October 15th of such year). 

e Your ability to electronically access Tax Documents provided within this Envelope is 
from the date of the consent, and they will remain available for 24 months from the time 
sent via the Envelope. The electronic delivery of Tax Documents may be terminated at 
any time by us. 

e If after we furnish you a Tax Document and you would like a paper copy, please see 
“Obtaining Copies of Electronic Communications” for instructions on how to do so. 


“Customer” means a person who obtains or has obtained a financial product or service from us. 


“Envelope” means the electronic container for the Communication(s) related solely to this 
transaction. Each Envelope may contain one or more Communications. 


This ERSD applies only to Communications included within this Envelope. Your consent to 
receive Communications within this Envelope does not affect the legal effectiveness, validity, or 
enforceability of any other consent to use electronic communications, records, and signatures 
that you may have given to Capital One. Further, your consent to receive Communications 
within this Envelope does not supersede or amend any other agreement you may have entered 
into with us regarding the delivery of electronic communications or notices related to that 
agreement. 


Delivery of Your Communications 


We will provide you Communications electronically through the DocuSign system. We will 
notify you by email when any Communications are available through DocuSign and the email 
will contain a link to the Communications. If your email address or other contact information 
changes, you must notify Capital One of such changes immediately by updating the profile on 
your Capital One account or if you are not a Customer, by following the process you used to 
originally provide us with your email address. 


Except to the extent prohibited by applicable law, email and Communications sent to you 
electronically shall be deemed delivered when we send them to your email address listed on your 
Capital One account if you are a Customer or the email address you provided us if you are not a 
Customer. If you fail to update or change an incorrect email address, you understand and agree 
that any electronic Communications shall nevertheless be deemed to have been provided to you 
if they were made available to you via a link sent to the email address that you provided us. 


The minimum system requirements for using the DocuSign system may change over time. Ata 
minimum, you will need the following: 


e An internet browser capable of accessing DocuSign; 

e An internet connection; and 

e A device (¢.g., a computer, tablet, mobile phone, etc.) and an operating system capable of 
supporting all of the above. You will also need a printer if you wish to print out and 
retain records on paper, and electronic storage if you wish to retain records in electronic 
form. 


The current system requirements are available on the DocuSign website. 


Termination and Changes 


We reserve the right to discontinue providing you with electronic Communications through the 
DocuSign system, or to terminate or change this ERSD. We will provide you with notice of any 
such termination or change as required by law. 


Obtaining Copies of Electronic Communications 


You will have the ability to download and print Communications we send to you through the 
DocuSign system during and immediately after the session and, if you elect to create a DocuSign 
account, you may access the Communications for 24 months after such Communications are first 
sent to you. At any time, you may request from us a paper copy of any Communication provided 
or made available electronically to you by us, including this ERSD. You may request delivery of 
such paper copies from us by contacting the sender for the Envelope or contacting Capital One 
using the contact information for your account. There are currently no fees for this service. 


How To Withdraw Your Consent 


You may decline to consent to this ERSD below. If you decline to receive Communications 
electronically, your transaction may be delayed as we will need to send them to you on paper. 


In addition, once you have consented, you may withdraw your consent during the signing session 
by utilizing the DocuSign drop down menu. If you choose to decline to proceed during the 
signing session, we will send all Communications to you via paper, which may delay your 
transaction. Your choice to withdraw will not impact past or future Envelopes or any other 
electronic consents you have provided as part of our relationship with you. 


Acknowledging Your Access and Consenting to Receive and Sign Documents Electronically 


TAfter reviewing the above terms and conditions of this ERSD, if you consent to receive 
Communications in electronic format as described above, select the check-box next to “I agree to 
use electronic records and signatures” before clicking “CONTINUE” within the DocuSign 
system. By selecting this check-box, you confirm that: 


e You can access and read this ERSD; 

e You can print out this ERSD, can save it electronically or send it to a location (i.e., your 
e-mail address) where you can print it out for your future reference and access; and 

e You have the necessary software and hardware to proceed. 


